Digital Personal Data Protection Act, 2023: What Banks Must Know
Passed in 2023, switched on in phases from November 2025, fully binding on banks from May 2027.
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first full law on personal data. It applies to personal data in digital form, or collected on paper and digitised later, and to processing outside India when it relates to offering goods or services to people in India. A bank is squarely inside it: account opening, KYC, loan files and transaction histories are all personal data.
The Act was passed in August 2023, but most of it was not switched on until the DPDP Rules, 2025 were notified on 13 November 2025, and even then in three phases. As of October 2026 the provisions setting up the Data Protection Board are in force, while the main duties on banks and other data fiduciaries start in May 2027.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
Key Terms
- Data Principal
- The individual the data is about. For a child (under 18) it includes the parent or lawful guardian.
- Data Fiduciary
- Whoever decides the purpose and means of processing. A bank processing its customers' data is a data fiduciary.
- Data Processor
- Anyone processing data on a fiduciary's behalf, such as a card-processing vendor or a cloud provider. The fiduciary stays responsible for the processor's work.
- Significant Data Fiduciary
- A fiduciary or class the government notifies on factors such as volume and sensitivity of data. It carries extra duties.
- Consent Manager
- A person registered with the Board who gives individuals one place to give, manage and withdraw consent.
- Personal data breach
- Any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises its confidentiality, integrity or availability.
When Each Part Applies
Set by notification G.S.R. 843(E), published 13 November 2025.
1
From
13 November 2025
What comes into force
Definitions, setting up the Data Protection Board, rule-making powers
2
From
One year later (November 2026)
What comes into force
Consent Managers and the Board's power over them
3
From
Eighteen months later (May 2027)
What comes into force
Notice, consent, legitimate uses, all fiduciary duties, rights of data principals, the Board's inquiry powers and penalties, and the omission of IT Act section 43A
| Phase | From | What comes into force |
|---|---|---|
| 1 | 13 November 2025 | Definitions, setting up the Data Protection Board, rule-making powers |
| 2 | One year later (November 2026) | Consent Managers and the Board's power over them |
| 3 | Eighteen months later (May 2027) | Notice, consent, legitimate uses, all fiduciary duties, rights of data principals, the Board's inquiry powers and penalties, and the omission of IT Act section 43A |
What a Bank Must Do Once Phase 3 Starts
- check_circleProcess personal data only with consent after a clear notice, or for a legitimate use the Act lists, such as compliance with a law.
- check_circleTake reasonable security safeguards to prevent personal data breaches, including in work done by its processors (section 8(5)).
- check_circleReport every personal data breach to the Board and to each affected customer (section 8(6)). Rule 7 requires a first report to the Board without delay and a detailed report within 72 hours of becoming aware, unless the Board allows longer.
- check_circleErase data when consent is withdrawn or the purpose is served, unless another law requires it to be kept. Banking and KYC record-keeping laws are such laws.
- check_circlePublish contact details of a Data Protection Officer or other responsible person, and run a working grievance mechanism.
- check_circleGive customers their rights: access to a summary of their data, correction and erasure, grievance redressal, and nomination of someone to act for them.
Quick practice on banking operations. No signup.
Maximum Penalties in the Schedule
Imposed by the Data Protection Board after an inquiry. These are monetary penalties; the DPDP Act creates no imprisonment.
| Breach | Up to |
|---|---|
| Failure to take reasonable security safeguards | ₹250 crore |
| Failure to notify the Board or affected individuals of a breach | ₹200 crore |
| Breach of additional obligations for children's data | ₹200 crore |
| Breach of Significant Data Fiduciary obligations | ₹150 crore |
| Breach of any other provision | ₹50 crore |
| Data Principal breaching her own duties (section 15) | ₹10,000 |
Where the Courseware and the Current Law Differ
Material written before November 2025 describes the DPDP Act as passed but not in force, and treats IT Act section 43A and the 2011 sensitive personal data rules as the whole of data protection law. Both are now only partly right. 43A still applies until May 2027, when phase 3 starts and removes it. A bank's data breach also triggers a separate CERT-In report within 6 hours under the 2022 CERT-In directions, which the DPDP regime does not replace.
How the IIBF Exam Tests This
- check_circleRole questions: is the bank the data principal, fiduciary or processor? The customer is the principal, the bank the fiduciary, its vendor the processor.
- check_circlePenalty ceilings: ₹250 crore for weak security safeguards is the highest. Expect it alongside the ₹200 crore entries as distractors.
- check_circleWho adjudicates: the Data Protection Board of India, with appeal to the TDSAT. Not the RBI, not CERT-In.
- check_circleTimelines: 72 hours to the Board under the DPDP Rules versus 6 hours to CERT-In. Candidates swap them.
FAQs
Is the DPDP Act 2023 in force?expand_more
Partly. The Board and definitions have applied since 13 November 2025. Consent Managers follow one year later, and the main obligations, rights and penalties 18 months later, in May 2027.
What is the maximum penalty under the DPDP Act?expand_more
Up to ₹250 crore, for failing to take reasonable security safeguards to prevent a personal data breach.
Within how many hours must a data breach be reported under the DPDP Rules?expand_more
Once rule 7 applies from May 2027, the Board must be told without delay, with a detailed report within 72 hours of becoming aware, unless the Board allows more time. Affected individuals must also be told without delay.
Does the DPDP Act replace section 43A of the IT Act?expand_more
Yes, but only from phase 3, 18 months after the 13 November 2025 notification. Section 44(2) of the DPDP Act omits 43A from that date.
Next steps
Take a full IIBF Cyber Crimes mock test120 questions, 2 hours, scored instantly.
